Discord functions as the town square for most crypto and NFT projects, hosting announcements, community discussion, and support in one place. That central role is exactly what makes it valuable to attackers. Discord reported taking action on more than three million accounts for deceptive practices, including phishing and financial scams, over a recent twelve month period, and separate research estimates that over one billion dollars in crypto was stolen through Discord based phishing in 2025 alone.
Why crypto and NFT communities live on Discord
Most legitimate projects use Discord for real time community management, announcing mint dates, answering questions, and building the kind of active following that gives a project credibility. That legitimate activity is also what scammers rely on to make their own messages look normal. A fake announcement dropped into a server that already has thousands of genuine members and a history of real updates does not stand out the way it would arriving cold in someone's inbox.
Server compromise and fake mint announcements
The most damaging pattern involves attackers gaining control of an official project server itself, rather than creating a fake one from scratch. Once inside, they post an announcement, usually about a surprise free mint, an urgent claim window, or a security migration, that directs members to connect their wallet through a malicious link. Because the message comes from the real server with the real member count and history, it carries far more credibility than a scam reaching out cold. The NFT platform Known Origin experienced exactly this in a documented incident, where its official Discord was compromised and used to advertise a fake free mint that stole assets from anyone who connected a wallet.
How attackers get in
Server compromises rarely involve breaking Discord itself. They typically start with a single moderator or administrator account being phished or having a session token stolen, or with a connected bot or webhook integration being exploited. Once an attacker controls even one privileged account, they can post as if they were the project team, adjust server settings, and reach every member instantly through what looks like an official channel.
Direct message scams
- Fake support accounts that message you privately after you post a public question in a support channel, offering to resolve your issue
- Fake giveaways sent by direct message claiming you have won an NFT or token drop and need to connect a wallet to claim it
- Fake verification bots that ask new members to run a command or click a link to prove they are human before accessing the server
- Impersonation accounts using a copied profile photo and a nearly identical username to a real moderator or project founder
A step by step walkthrough of a compromised server attack
Understanding the full sequence of a server compromise attack makes clear why the warning arrives too late for many members by the time anyone realizes something is wrong.
- An attacker phishes or otherwise steals the login credentials or session token of a moderator, administrator, or a bot integration with elevated permissions in the target server
- The attacker waits for a natural moment, often late at night in the project's primary time zone, to reduce the chance of a real team member noticing quickly
- A post appears in the announcements channel, using the real account, the real role color, and the real history of legitimate updates, describing a surprise mint, airdrop, or urgent security migration
- The message includes a link to a convincing but fraudulent website, often a near identical clone of the project's real site with a different domain
- Members who connect their wallet and sign the requested transaction have their assets drained within minutes, sometimes before the compromised account is even noticed and removed
- The real project team typically discovers the compromise only once members begin reporting losses, by which point the damage to the earliest connecting members is already done
Fake giveaway and NFT specific patterns
NFT communities face a version of these scams tailored specifically to how NFTs are bought, sold, and displayed. A common pattern involves a direct message claiming you have been selected for a free mint or a rare item giveaway, with a link to a site that mimics a well known marketplace. Because many NFT transactions already involve signing approvals for a marketplace contract to access a wallet's tokens, victims are sometimes less alert to a signature request than they would be for a plain transfer, which is exactly why this category of scam remains effective even among experienced collectors. Our guide on how NFT scams work covers the marketplace specific versions of this pattern in more detail.
Fake verification bots that drain wallets
New members joining a crypto Discord server are frequently routed through a verification step before they can chat. Legitimate versions of this exist to filter out spam accounts. The fraudulent version asks a new member to connect their wallet and sign a transaction to prove ownership, but the transaction actually being requested grants the attacker approval to move tokens or NFTs out of the wallet. Because this happens immediately upon joining, before a person has built any sense of the server's normal behavior, it catches people off guard more often than a scam that arrives later.
No legitimate verification step, giveaway claim, or support process ever requires you to sign a wallet transaction. Signing is the moment permission is actually granted, and it should be treated as equivalent to handing over control, not as a routine formality.
The scale of the problem
The pattern of compromised moderator accounts and hijacked webhooks posting fraudulent mint links has become common enough that security researchers now treat it as a routine, expected part of running a public crypto Discord server rather than a rare event. Recurring losses tend to come from these compromised internal accounts, not from any flaw in Discord's own platform, which means the responsibility for prevention sits heavily with how individual project teams secure their own admin and moderator accounts.
How to protect yourself in crypto Discord servers
- Reach a project's Discord server only through a link on the project's official website, never through a link shared by another user
- Treat every direct message offering help, a giveaway, or urgent account action as a scam by default, since real teams rarely message first
- Never sign a wallet transaction as part of a verification, giveaway claim, or support process, since this is how wallet draining attacks actually work
- Check whether an announcement about a surprise mint or urgent claim matches what the project has said on its official website or verified social media account before acting
- Use a separate, low balance wallet for connecting to any new or unfamiliar site linked from a Discord server
- Enable Discord's built in safety settings that restrict direct messages from server members you are not already friends with
- Pause before acting on any announcement that creates time pressure, since urgency is used deliberately to prevent members from cross checking the claim elsewhere
What project teams and moderators can do to reduce risk
Because most large scale losses trace back to a single compromised privileged account rather than a flaw in Discord itself, the strongest defenses sit with how project teams secure their own admin and moderator access. Enabling hardware security key or authenticator based two factor authentication on every account with elevated server permissions closes off the most common entry point attackers use. Limiting how many accounts hold administrator level permissions, auditing connected bots and webhooks regularly for ones that are no longer needed, and establishing an internal rule that no announcement involving a wallet connection goes out without a second team member's confirmation through a separate channel, such as a phone call or a private, previously established communication method, can prevent a single stolen credential from reaching an entire community instantly.
The mechanics of how a signed transaction actually hands over control of your assets are covered in more depth in our guides on wallet draining attacks and malicious token approvals.
What to do if you already signed a malicious transaction
Act quickly once you realize a Discord link or bot led to a suspicious signature, since some drains happen in stages rather than all at once. Use a reputable token approval checker to see exactly what permissions the contract in question was granted, and revoke any that remain active, even if it looks like the wallet has already been fully emptied, since a lingering approval can be used against future deposits into the same wallet. Move any remaining funds and NFTs to a newly created wallet immediately, and treat the compromised wallet as permanently unsafe rather than something to keep using cautiously.
Report the incident to the project team through their official website or verified social media, not through the Discord server itself if you suspect it is still compromised, since your report can help them warn other members before more people connect their wallets. Document the transaction hash, the malicious contract address, and the Discord message or link that led to it, and file a report with the FBI's Internet Crime Complaint Center. Our guide on the first 24 hours after a crypto theft covers this process in fuller detail.
Frequently asked questions
Almost always by compromising a single moderator or administrator account, often through phishing, or by exploiting a connected bot or webhook integration. Once they control one privileged account, they can post announcements that appear to come from the official project team to every member at once.
No legitimate verification process requires you to sign a wallet transaction. If a verification bot asks you to connect a wallet and sign something to prove you are human or eligible to chat, treat it as a scam, since signing is how permission to move your assets is actually granted.
Revoke any token approvals granted to the suspicious contract as quickly as possible using a reputable approval checking tool, and move any remaining assets in that wallet to a new, uncompromised wallet. Document the transaction and the Discord server involved before doing anything else with that wallet.
Discord can suspend the accounts or bots involved and has taken action against millions of accounts for this kind of abuse, but it has no ability to reverse a blockchain transaction or return stolen funds directly. Reporting still matters for getting malicious accounts removed and supporting any broader investigation.
Common signs include an announcement or message that team members did not write, unexpected role or permission changes, a moderator suddenly online at unusual hours, or member reports of a suspicious link posted in an official channel. Teams that regularly audit admin accounts, connected bots, and webhook integrations tend to catch a compromise faster than teams that only investigate after members start reporting losses.
Sources and further reading
- Discord Scams: 12 types, warning signs, and how to stay safe · Moonlock
- What Is a Discord Server Hack Scam in Crypto Projects? · MrDeFi